Claude
Anthropic PBC
Short answer
Short answer: Claude is one of the lower-risk major LLMs for work on its commercial tiers — no training on your data and a strong certification set. On the Free/Pro/Max consumer app, opt out of training. You still need a policy for what data goes in, and a DPA (commercial) for personal data.
At a glance
- Vendor / legal entity
- Anthropic PBC
- Headquarters
- 🇺🇸 San Francisco, US
- Category
- LLM / Chat
- Ownership / jurisdiction
- US public-benefit corporation (Anthropic PBC), San Francisco; EU services provided by Anthropic Ireland Limited, Dublin.
- Trains on your data?
- On by default — opt-out available
- Data hosting & residency
- US-based processing; EU services are provided by Anthropic Ireland Limited, with SCCs for transfers in the DPA.
- Sub-processors
- Sub-processors are published at trust.anthropic.com/subprocessors, with 15 days' notice of changes.
- Enterprise tier
- The commercial tiers (API, Team, Enterprise, Claude for Work/Government/Education) are not used for training, and a DPA is auto-incorporated into the Commercial Terms. The Aug 2025 consumer-terms update applies only to Free/Pro/Max.
- Certifications
- SOC 2 Type I & II · ISO 27001:2022 · ISO/IEC 42001:2023 · HIPAA-ready (BAA available)
- Pricing model
- Freemium: Free, Pro/Max subscriptions, per-seat Team/Enterprise; usage-based API.
Why this rating
Claude's commercial path — the API, Team, Enterprise, Claude for Work/Government/Education — is excluded from training and backed by a strong certification set (SOC 2 Type II, ISO 27001, ISO 42001, HIPAA-ready) with EU services via Anthropic Ireland and SCCs. One caveat lowered the score from being clear-cut: an August 2025 consumer-terms change means Free/Pro/Max chats are now used for training unless you opt out. Low overall for the governed tiers, with that consumer nuance flagged.
What it is
Claude is Anthropic's conversational assistant. Its governance differentiator is that the commercial tiers (API, Team, Enterprise, Claude for Work) do not use your prompts or outputs to train models, and it holds a broad certification set (SOC 2, ISO 27001, ISO 42001). Note the August 2025 consumer-terms change: Free/Pro/Max chats are now used for training unless you opt out — so the consumer app is no longer no-training-by-default, while the commercial path still is.
Legal & compliance examples
How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.
Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.
Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.
These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.
Frequently asked questions
Does Claude train on your data?
The commercial tiers (API, Team, Enterprise, Claude for Work) do not. Since an August 2025 update, the Free/Pro/Max consumer plans use your chats for training unless you opt out.
Is Claude GDPR-compliant?
Anthropic offers a DPA, EU services via Anthropic Ireland, and holds SOC 2 / ISO 27001, so Claude can be operated GDPR-compliantly with the right tier and controls. Compliance is a property of your deployment, not just the tool.
How do I govern Claude at work?
Qadar AI Shield discovers Claude usage, redacts personal data on the device before it reaches the tool, and lets you allow-list it per group with an audit trail.
Sources
Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.
Govern this tool
Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.
Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.